Default Password Reset Restrictions
Default restrictions for password reset flows. Currently, they are (in this order):
- Nonexistent User Restriction
- Invalid User Restriction
- Locked User Restriction
By default, these restrictions do not report violations and therefore prevent user enumeration. To include custom restrictions or to configure restrictions for other types of self-service flows, the "Custom Public Self-Service Restrictions" plugin can be used.
allowLockedUser) If enabled, users that are locked because of too many failed password checks (lock reason "LockReason.TooManyAuthAtts.PASSWORD") are allowed to perform a password reset flow. Locked users with any other lock reason cannot reset their password. To allow other lock reasons, use the "Locked User Restriction" plugin with "Custom Public Self-Service Restrictions".
nonexistentUserFeedback) If enabled, nonexistent users attempting to start a password reset flow receive an error response with error code "USER_NOT_FOUND". Otherwise, the flow would also continue for nonexistent users but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
invalidUserFeedback) If enabled, invalid users attempting to start a password reset flow receive an error response with error code "USER_INVALID". Otherwise, the flow would also continue for invalid users, but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
lockedUserFeedback) If enabled, locked users attempting to start a password reset flow receive an error response with error code "USER_LOCKED". Otherwise, the flow would also continue for locked users but fail in the verification step (to protect against user enumeration).
Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.
type: DefaultPasswordResetRestrictions
id: DefaultPasswordResetRestrictions-xxxxxx
displayName:
comment:
properties:
allowLockedUser: false
invalidUserFeedback: false
lockedUserFeedback: false
nonexistentUserFeedback: false